nerdexam
Isaca

CISM · Question #28

Which of the following is MOST effective in preventing the introduction of vulnerabilities that may disrupt the availability of a critical business application?

The correct answer is B. Change management controls. Change management controls are most effective in preventing vulnerabilities that disrupt availability because they ensure all modifications to critical systems are systematically planned, reviewed, tested, and approved, reducing the risk of introducing errors or…

Submitted by obi.ng· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST effective in preventing the introduction of vulnerabilities that may disrupt the availability of a critical business application?

Options

  • AA patch management process
  • BChange management controls
  • CVersion control
  • DLogical access controls

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    82% (18)
  • C
    5% (1)
  • D
    9% (2)

Why each option

Change management controls are most effective in preventing vulnerabilities that disrupt availability because they ensure all modifications to critical systems are systematically planned, reviewed, tested, and approved, reducing the risk of introducing errors or misconfigurations.

AA patch management process

A patch management process addresses existing vulnerabilities but doesn't prevent the introduction of new ones through uncontrolled changes.

BChange management controlsCorrect

Change management controls are designed to ensure that all changes to an IT environment, including applications, infrastructure, and configurations, are systematically planned, reviewed, tested, and approved before implementation. This structured process significantly reduces the likelihood of introducing vulnerabilities or misconfigurations that could lead to outages and disrupt the availability of critical business applications.

CVersion control

Version control tracks changes to code and documents but doesn't inherently prevent the introduction of vulnerabilities or misconfigurations into a live production environment without broader change management.

DLogical access controls

Logical access controls prevent unauthorized access, which is crucial for confidentiality and integrity, but less directly for preventing new vulnerabilities that disrupt availability from being introduced by authorized but faulty changes.

Concept tested: Preventing vulnerabilities via change management

Source: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/change-management

Topics

#Change Management#Vulnerability Prevention#Availability#Application Security

Community Discussion

No community discussion yet for this question.

Full CISM Practice